Account IDs Are Useless in URLs? X's Flaw Exposes Users to Crypto Scammers' New Exploits
A flaw identified by BleepingComputer allows scammers to manipulate URLs, presenting a tweet as if posted by a legitimate account, while redirecting users to fraudulent content. X's mechanism of using the status ID for post retrieval without validating the account name facilitates scammers in modifying even high-profile account names.
